Security readout for executives and security teams
Plain-English summary
This issue affects the D-Link DSL-6740U gateway Rev. H1. If an administrator is logged in, a remote attacker may abuse the admin's browser to submit unauthorized setting changes, including administrator credential changes or enabling remote management.
Executive priority
Treat this as a high-priority legacy router exposure if the device is still deployed. It can affect administrative control of network edge equipment, but current public evidence does not show active exploitation.
Technical view
CVE-2013-6811 describes multiple CSRF flaws in DSL-6740U Rev. H1 administrative functions, including port forwarding, port triggering, URL filtering, print server, QoS queue, and QoS classification configuration. The source bundle provides no CVSS score, patch status, or exploit evidence.
Likely exposure
Exposure is likely limited to legacy D-Link DSL-6740U Rev. H1 gateways. Risk is highest where administrators browse the web while authenticated to the router UI, or where management access is broadly reachable.
Exploitation context
The sources do not report active exploitation, and the CVE is not in KEV. The described attack depends on hijacking an authenticated administrator's browser session to submit configuration-changing requests.
Researcher notes
The CVE record lists broad CSRF impact across several router configuration pages but lacks CVSS, CWE, CPE, and remediation detail. Analysis should avoid extending impact beyond DSL-6740U Rev. H1 without vendor evidence.
Mitigation direction
- Check D-Link guidance for DSL-6740U Rev. H1 firmware or replacement options.
- Restrict administrative access to trusted management networks only.
- Disable remote management unless it is explicitly required.
- Review and reset administrator credentials after suspected exposure.
- Retire the device if no supported vendor remediation exists.
Validation and detection
- Inventory networks for D-Link DSL-6740U Rev. H1 gateways.
- Confirm whether administrative interfaces are reachable from untrusted networks.
- Review configuration for unexpected remote management, forwarding, filtering, print, or QoS changes.
- Verify current firmware and support status against vendor guidance.
- Check logs or change history for suspicious administrator configuration changes.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2013-6811 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89612CVE reference · x_refsource_MISC
- https://web.archive.org/web/20131208091355/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10005CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
